Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_5if3mzfr9pn
- Transfer
- acht_sim_meri_ah47837rc0h · $354.20 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An alert fired on 2026-09-17 for entity enti_sim_meri_5if3mzfr9pn under the sanctions_or_pep detector after a settled ACH debit of $354.20 on 2026-09-06 from that entity, part of the Meridian Remit program (declared monthly volume $1,200,000.00, rails ach/wire/swift, countries US/MX/PH).
What the evidence shows. The transfer-level skoor is 20, band clear, with hard_signal false. The only contributing signal is entity.high_risk (+20). The entity record shows verification status VERIFIED, pep=no, review reasons none, last screened 2026-08-27 (not stale), and country US. The transfer itself is SETTLED with no return code, indicating no rejection or reversal. There are no prior dispositions on this alert. Program-level KRIs show several breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate, sanctioned_country_transfers=1), but none of these are tied in the evidence to this specific entity or transfer.
What was checked. Reviewed the alert's skoor, band, and hard_signal fields; the entity's screening, verification, and PEP status; the transfer's status and return code; and the program's KRI panel for any linkage to this subject. No stale screening, no PEP flag, no denial or return on the transfer, and no prior alert history were found.
What is recommended. Close this alert. The screening result is clear-band with no hard signal, the entity is verified and not PEP, screening is current, and the associated transfer settled without incident. The program-level KRI breaches (e.g., sanctioned_country_transfers, reserve_coverage_ratio) are noted for program-level monitoring but do not, on this evidence, tie to this specific entity or transfer, so they do not change the disposition of this alert. A person should still review program KRI breaches separately if not already tracked elsewhere.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer skoor is 20, band clear, hard_signal false — the only signal present is entity.high_risk, already accounted for in the low score.
- Entity is VERIFIED, pep=no, review reasons none, and screening is current (2026-08-27), showing no stale or unresolved screening issue.
- The associated transfer is SETTLED with return code none, showing no rejection, reversal, or unauthorized-return event tied to this specific activity.
- No prior dispositions exist on this subject, so there is no pattern of repeat alerts to escalate.
- Program-level KRI breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate, sanctioned_country_transfers) are present but not evidenced as connected to this entity or transfer, so they are noted as context rather than grounds for escalation on this alert.
- The transfer has already settled, so a hold or release recommendation does not apply.
Evidence
{
"n": 902,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.